
Oralyzer
Python-based open redirect vulnerability scanner that fuzzes URLs to detect header, JavaScript, and meta tag-based redirects, with integrated…

Python-based open redirect vulnerability scanner that fuzzes URLs to detect header, JavaScript, and meta tag-based redirects, with integrated…

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Wordlist of potentially dangerous filenames and paths for web content discovery, directory brute-forcing, and fuzzing to uncover hidden sensitive…

Fast HTTP fuzzer and enumerator for content discovery, credential bruteforcing, and response filtering with real-time display and flexible…

Multi-threaded vulnerability scanner for CVE-2026-0740, a path traversal in Ninja Forms File Uploads. Detects vulnerable WordPress targets, uploads a…

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Set of tools to audit SIP based VoIP Systems

BurpSuite plugin for HTTP packet analysis and fuzzing dictionary generation. Extracts parameters, paths, and files from requests, counts frequency,…

Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

A high performance offensive security tool for reconnaissance and vulnerability scanning

Multi-threaded web reconnaissance tool for directory/file enumeration, subdomain discovery, virtual host detection, and parameter fuzzing, designed…

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing